Files
bchanot-cv/docker-compose.yml
T
Bastien Chanot ba13d697a5 fix(security): unprivileged nginx + security headers on every location
- base image -> nginxinc/nginx-unprivileged:1.28-alpine, digest-pinned
  (BREAKING for the docker path: container port 80 -> 8080; compose
  mapping/healthcheck updated in the same change, cap_add dropped)
- nginx add_header inheritance fix: shared snippets file re-included in
  every location that sets Cache-Control -- previously ALL security
  headers were dropped on real responses (verified live before/after)
- server_tokens off; set_real_ip_from restricted to 127.0.0.1
- expires directives removed (duplicated Cache-Control); gzip_types
  text/html redundancy removed (nginx -t warn)
2026-07-05 14:10:55 +02:00

36 lines
918 B
YAML

# docker-compose for bchanot.fr static site.
#
# Usage:
# cp .env.example .env
# # edit .env to set the host port (default 8080)
# docker compose up -d --build
#
# Host port is bound to 127.0.0.1 so the container is reachable only by a
# reverse proxy running on the same machine. Change to 0.0.0.0:${PORT} if
# you need LAN access for testing.
services:
bchanot-web:
build:
context: .
dockerfile: Dockerfile
image: bchanot-web:latest
container_name: bchanot-web
restart: unless-stopped
ports:
- "127.0.0.1:${PORT:-8080}:8080"
healthcheck:
test: ["CMD", "wget", "-qO-", "http://127.0.0.1:8080/"]
interval: 30s
timeout: 3s
retries: 3
start_period: 5s
read_only: true
tmpfs:
# nginx-unprivileged writes pid + temp files under /tmp only.
- /tmp
security_opt:
- no-new-privileges:true
cap_drop:
- ALL